Lipad Checkout Security & Risk Analysis

wordpress.org/plugins/lipad-checkout

Accept payments on WooCommerce via the Lipad Standard (Hosted) Checkout. Supports Sandbox and Production setups.

0 active installs v3.0.6 PHP 7.4+ WP 5.8+ Updated Jun 18, 2026
kenyalipadmpesapaymentswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lipad Checkout Safe to Use in 2026?

Generally Safe

Score 100/100

Lipad Checkout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "lipad-checkout" v2.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. It reports no known vulnerabilities in its history and the code analysis shows no dangerous functions, SQL queries without prepared statements, or external HTTP requests. The absence of taint analysis findings, critical or high severity, further suggests a lack of immediately exploitable vulnerabilities related to data sanitization and flow.

However, several concerning signals emerge from the code analysis. The most significant is that 100% of the identified outputs are not properly escaped, representing a potential Cross-Site Scripting (XSS) risk. Additionally, the plugin has no recorded capability checks or nonce checks. While the attack surface is reported as zero, the presence of file operations without explicit mention of authorization mechanisms or proper handling raises a flag. The lack of any recorded vulnerabilities in its history, while positive, could also indicate limited past security auditing or a lack of testing for specific attack vectors.

In conclusion, the plugin has several strengths, particularly in its handling of SQL and absence of known exploits. Nevertheless, the unescaped output is a critical concern that requires immediate attention. The lack of capability and nonce checks, coupled with the file operation, present potential weaknesses that, while not directly exploited by the static analysis, could be leveraged by attackers in conjunction with other vulnerabilities or misconfigurations. A thorough review and remediation of these identified code quality issues are highly recommended.

Key Concerns

  • Output not properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Lipad Checkout Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Lipad Checkout Release Timeline

v3.0.6Current
v3.0.5
v3.0.4
v3.0.3
v3.0.2
v3.0.1
v3.0.0
v2.0.0
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
Code Analysis
Analyzed Mar 17, 2026

Lipad Checkout Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Lipad Checkout Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterwoocommerce_payment_gatewayslipad-payment-gateway.php:25
actionplugins_loadedlipad-payment-gateway.php:31
actionwp_enqueue_scriptslipad-payment-gateway.php:102
actionwoocommerce_api_lipad_payment_webhooklipad-payment-gateway.php:105
Maintenance & Trust

Lipad Checkout Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJun 18, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Lipad Checkout Developer Profile

Lipad

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lipad Checkout

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lipad-checkout/assets/css/lipad-checkout.css/wp-content/plugins/lipad-checkout/assets/js/lipad-checkout.js
Version Parameters
lipad-checkout/assets/css/lipad-checkout.css?ver=lipad-checkout/assets/js/lipad-checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
lipad-checkout-wrapperlipad-checkout-form
HTML Comments
<!-- Lipad Checkout Gateway Options --><!-- Lipad Checkout Form -->
Data Attributes
data-lipad-checkout-gateway-id
JS Globals
lipadCheckoutConfig
REST Endpoints
/wp-json/lipad-checkout/v1/payment_request
Shortcode Output
[lipad_checkout_form]
FAQ

Frequently Asked Questions about Lipad Checkout